Steve Syfuhs @syfuhs.net · 40mstatic.klipy.comOzzy Osbourne Calls SharonALT: Ozzy Osbourne Calls Sharon 020
Steve Syfuhs @syfuhs.net · 1hWorst thing I've ever seen. Shame brought to you and your family. Yadda yadda. 000
Steve Syfuhs @syfuhs.net · 18hAll good. A wonderful distraction. Only so many ways to keep busy when people die without going crazy. All things considered I'm all for making a better UX for it. Even all for making a better password manager all up. 040
Steve Syfuhs @syfuhs.net · 19hstatic.klipy.comJack Black Nodding in Nacho LibreALT: Jack Black Nodding in Nacho Libre 120
Steve Syfuhs @syfuhs.net · 19hCooooooomplicated af to say the least. We've been building out a ton of functionality on this front through MXC as well as Windows internals. github.com/microsoft/mxc It's somewhere between a spiritual successor and vnext of appx.github.comGitHub - microsoft/mxc: Policy-driven, layered isolation and containmentPolicy-driven, layered isolation and containment . Contribute to microsoft/mxc development by creating an account on GitHub. 010
Steve Syfuhs @syfuhs.net · 19hCertainly. No argument on that. I'm not convinced there's a way that will happen at "all apps" scale though. That's the crux of my point. Unless that happens there isn't a whole lot we can that is generally usable. It's a painful line to straddle. 110
Steve Syfuhs @syfuhs.net · 20hThis is my point. UWP works the same way (appx). The fact that android doesn't have that third tier of arbitrary app is what allows it to make the promises it can, which makes it an unequal comparison. 210
Steve Syfuhs @syfuhs.net · 20hYou have system executable processes but those are OS provided. There is no process that isn't system and isn't package isolated. Windows has system, UWP, or arbitrary app. That latter bit is what makes this not equivalent. We could kill that third tier and it's be identical isolation promises. 110
Steve Syfuhs @syfuhs.net · 20hAgain, you're conflating isolation. An android app is equivalent to a UWP app. There is no concept of a non-uwp equivalent app on Android. 100
Steve Syfuhs @syfuhs.net · 20hI actually don't believe that to be true. I don't think they meet that claim. 000
Steve Syfuhs @syfuhs.net · 20hI'm saying not every single way promises it can't exploit the OS. The only way it holds its promises is through strict guarantees of app installation through vetted channels. I.e. A store. 100
Steve Syfuhs @syfuhs.net · 20hAnd no, android does not protect an app's data from side loaded apps. It protects against apps side loaded a specific way. 110
Steve Syfuhs @syfuhs.net · 20hAgain, Windows has that same thing. Same semantic promises. Store app or UWP or Low IL take your pick for a name. It all comes down to how that app gets onto the device. A side loaded app is no different. 110
Steve Syfuhs @syfuhs.net · 21hIf you want the same isolation you need the same isolation. It's a two way street. Go force all apps through the store. Problem solved. That was S Mode. Worked great if you had store apps. Conversely iOS ONLY has store apps. 020
Steve Syfuhs @syfuhs.net · 21hOkay but you keep making comparisons that aren't equivalent. We have the iOS equivalent on Windows today and it's been there since Win8. What makes iOS and Android safe is the store enforcement. The minute you side load an app all bets are off. 210
Steve Syfuhs @syfuhs.net · 21hThere is no world in which a user can touch a file that malware cannot. That is the fundamental problem. 141
Steve Syfuhs @syfuhs.net · 21hThe saying "perfect is the enemy of good" is only applicable when the thing you're trying to build is materially better than what exists today. Getting to something "good" that is materially better than today's "good enough" is a monumental undertaking. 100
Steve Syfuhs @syfuhs.net · 02/10/2026You don't need debug privilege to get into an adjacent process as the same user. That alone makes this a pain in the ass to defend. AVs are an unsuitable security boundary. There's no guarantee it works, otherwise what's from saying an AV is present so no point in doing anything? 100
Steve Syfuhs @syfuhs.net · 02/10/2026Okay but what if we gave the screwdriver a chance. First it starts with a board with a nail in it and then they build another board with an even bigger nail and then eventually the biggest board with the biggest nailll.static.klipy.comKang and Kodos Laughing in SpaceALT: Kang and Kodos Laughing in Space 0471
Steve Syfuhs @syfuhs.net · 02/10/2026In fairness to the parrot, I don't think they know what 'stochastic' means. 020
Steve Syfuhs @syfuhs.net · 02/10/2026That's not really how process trees work. Also, you don't want to indiscriminately do that. What if process A does the Hello prompt then launches a browser? The browser has access to what? Things A had, or nothing, or everything? How long does that prompt grant? Lifetime of the app? 10 min? 100
Steve Syfuhs @syfuhs.net · 02/10/2026Sure, why not? If someone wants to build it, more power to them. 000
Steve Syfuhs @syfuhs.net · 02/10/2026Okay but how do you determine only browsers should read those cookies? Side note. We already have this kind of protection through normal SSO capabilities as well as WAM. 200
Steve Syfuhs @syfuhs.net · 02/10/2026I don't specifically know, but if thats the case then we're done. We've built it and have parity. It's been that way for a decade. 000
Steve Syfuhs @syfuhs.net · 02/10/2026I haven't looked in forever but I think they bruteforce it by prompting on every unique process. 000
Steve Syfuhs @syfuhs.net · 02/10/2026Rogue apps in the store happen, though infrequently, and we clean them up before they cause real problems, but back to the all vs some problem. If all apps get all, that promises nothing new. If all apps only get their own, that's also useless because you need to get the passwords into that silo. 100
Steve Syfuhs @syfuhs.net · 02/10/2026So you can say "only creds with an app identity can access creds". Alright, that's any app from the Store. We built that already. That's the IL-aware bit. But then the question is, should the app see only its own creds or all the users creds? How do you decide which apps get that privilege? 200
Steve Syfuhs @syfuhs.net · 02/10/2026Process identity and intent is "should this process be allowed to see the raw credential"? What is the deciding factor there? That Kernel knows its PID 1234 making the call with a name of program.exe isn't very meaningful. I could create explorer.exe and all it does is siphon all the creds. 100
Steve Syfuhs @syfuhs.net · 02/10/2026Between home and work I have 2 desktops, 2 laptops, a phone, and a tablet all used daily, not to mention the myriad of dev devices floating around. Not syncing between these would be worse than having no password manager. Yes kernel knows and you can't spoof it. That doesn't solve the problem. 210
Steve Syfuhs @syfuhs.net · 02/10/2026Saved for posterity: syfuhs.net/adventures-i...syfuhs.netAdventures in Credential Manager TriviaCredential Manager is a thing in Windows and it manages your credentials. 041
Steve Syfuhs @syfuhs.net · 02/10/2026Can I sue them for murdering the braincells in my head after reading that 010
Steve Syfuhs @syfuhs.net · 02/10/2026"Simply" is the dead giveaway. Nothing is ever simple. VBS gives you execution, not storage. TPM gives you storage, but not portability. App identification is a universally hard problem and the thing you care about more so is intent vs identity because every signal from VTL0 to VTL1 is untrusted. 130
Steve Syfuhs @syfuhs.net · 02/10/2026No they won't. We know this. We live this. Apple has the luxury of owning the entire stack down to the hardware. Android, nearly. Windows does not and that means it's a much harder problem because we're playing with different building blocks. 130
Steve Syfuhs @syfuhs.net · 02/10/2026Suffice to say the UX remains. It's not a generic secret store. It shouldn't be used as one. The Windows SSO capabilities continue to be pretty solid, but as we move to a more modern world, we end up with less and less utility of it with newer protocols that aren't password-based. Ah well. 5130
Steve Syfuhs @syfuhs.net · 02/10/2026The Cred APIs are just wrong for extended functionality. Adding properties is doable, but protected properties notsomuch. Length constraints are a big problem. The security issues I mentioned up thread couldn't be addressed at the UX layer. It needed more work. 120
Steve Syfuhs @syfuhs.net · 02/10/2026They did a fantastic job building out the UX. It was fully functional. I used it and actually still have some records sitting in my corp credman database still. It was pretty cool. Unfortunately it never shipped because it wouldn't scale in ways we needed. 130